PlaysoloistStringsUkulelePrivacy
Soloist Ukulele Privacy Policy
Last updated: 11 July 2026
Soloist Ukulele is designed so the most sensitive part of practice — the sound of you playing — never leaves your iPhone or iPad.
Audio, imports, and practice data
Microphone listening, tuning, recording, transcription, note-level grading, lesson progress, takes, imported songs, and practice history are processed or stored on your device. No audio recording, raw microphone samples, imported music, or transcription is uploaded to our servers or to Coach.
The optional Coach account
The tuner, course, songs, imports, playback, and on-device grading require no account. If you choose network Coach, Sign in with Apple provides a stable, pseudonymous app-specific user identifier. Soloist Ukulele requests no Apple name or email scope. Our service stores that pseudonymous identifier while the Coach account is active to secure your quota and, when applicable, your Pro entitlement mirror across your devices.
What Coach sends
When you ask Coach a question, the text you type and an optional short numeric summary of your latest graded take — such as pitch and timing percentages — pass through our AWS service in Sydney to the OpenAI API solely to generate a reply. Audio, recordings, imported songs, full practice history, and note-by-note take data are never sent.
We do not store Coach message text in our database. OpenAI API requests are sent with provider storage disabled. OpenAI states in its API data-controls notice that API data is not used to train models by default unless the account opts in; provider abuse-monitoring logs may retain prompts and replies for up to 30 days. Do not include personal or sensitive information in a Coach message.
Purchases and catalog updates
- Purchase verification: Apple processes subscriptions. When you use network Coach with Pro, our server verifies Apple's signed StoreKit transaction. It contains product, transaction, environment, and expiry details — not your name, card number, or other payment information.
- Catalog updates: the app may request a signed public catalog update without sending an account identifier, purchase identifier, practice result, or audio.
What we do not do
- No advertising and no advertising identifier.
- No third-party analytics or tracking SDKs.
- We do not sell personal data. Coach text is disclosed to OpenAI only when you invoke Coach, as described above.
Retention and deletion
Our live database stores your pseudonymous app-specific Apple user identifier, a monthly Coach counter, and, when applicable, purchase-entitlement and subscription-membership records. The profile remains until account deletion. Purchase records remain until deletion or their scheduled expiry; monthly counters also have a scheduled expiry.
You can delete those server-side records directly in Soloist Ukulele → Toolkit → Settings → Privacy → Delete Coach Account. Deletion removes those account rows and clears the local Coach session. It does not cancel an Apple subscription or erase on-device practice data.
To stop an already-issued session from restoring deleted data, the live service logically retains a one-way identity hash and revoked-session boundary for 31 days. It also logically retains a one-way hash of each high-entropy Sign in with Apple nonce and a server ordering number for 2 hours, solely to reject replayed pre-deletion credentials. These scheduled-expiry records use DynamoDB Time to Live: after the stated logical period the service ignores them and schedules removal, but AWS may complete physical deletion later.
A separate deletion ledger stores only one-way identity and account-lifecycle hashes, timestamps, and transaction-only replay progress—never a raw Apple identifier, Coach text, or audio. Each ledger event is logically active for exactly 70 days, then ignored and scheduled for Time to Live removal; physical deletion may lag.
Encrypted AWS disaster-recovery history may retain prior versions of both database tables for up to 35 days, including records already removed from the live tables. Recovery history is not available to normal app requests. Any restored account table remains isolated until the current hashed deletion ledger has been replayed, so completed deletions are reapplied while a proven later account recreation is preserved. An earlier version of a ledger event can likewise remain inside that ledger table's separate 35-day encrypted recovery history.
Signing into Coach again after deletion creates a fresh account lifecycle and may recreate verified purchase records.
Children
Soloist Ukulele is not directed at children under 13. A parent or guardian who believes a child submitted personal information through Coach can contact us to request deletion.
Contact
mitsi@playsoloist.com · Soloist Ukulele Support · Soloist Ukulele Terms